Skip to main content
  • Platform
  • Solutions
    • COIOS - Sovereign Agentic AI
    • FedX - Sovereign Federated AI
    • CORPEX - Banking & Payments
    • Trust - Identity & Digital Trust
    • Advanced Analytics
  • Engage
  • Industries
  • Principles
  • The Work
  • Thinking
  • About
  • Take a Position
E-Group E-Group
Legal · Data Protection
 

Privacy Policy.

Effective 8 April, 2021
 

Introductory Provisions

E-Group ICT Software Informatikai Zártkörűen Működő Részvénytársaság (2 Alsó Törökvész út, Budapest 1022 Hungary; company registration number 01-10-045390; Court of Registry: Court of Budapest-Capital Regional Court; official address info@egroup.hu / egroup.hu/company/contact-us) — hereinafter "E-GROUP", "service provider", "data controller" — as a service provider and data controller handles the data of the persons registered on the website during the operation of the website in order to provide them with a suitable service.

By using the https://www.egroup.hu website (hereinafter: website), you agree to be bound by the provisions of this Privacy Policy.

As data controller, Service Provider acknowledges that the content of this Privacy Policy is obligatory and undertakes that all data management and data processing related to its activities comply with the requirements specified in this Privacy Policy and the applicable legislation. By publishing this Privacy Policy, Service Provider ensures that the natural persons using the Services become acquainted with the relevant data protection rules before using the Service.

Service Provider provides services to both natural and legal persons, unincorporated companies and individuals (including, for example, lawyers, patent attorneys, notaries, sole proprietors and sole proprietorships). The service mostly involves the processing of personal data, which may not be separate from the processing of company data. As personal data is any information about the data subject (Section 3 (3) of the Privacy Act), the data of employees, senior executives and private owners of companies — name, email address, telephone number and similar — are also considered personal data.

Service Provider continuously publishes this Privacy Policy on the www.egroup.hu website, and reserves the right to modify this Privacy Policy at any time, in which case it publishes a notice of the relevant changes on the www.egroup.hu website.

Service Provider describes the principles of data processing below, presents the expectations it has formulated and adheres to, and declares that its data processing principles are in accordance with the current data protection legislation in force, as contained in this Privacy Policy.

In order to avoid and prevent abuses, Service Provider stores certain personal and transactional data about the affected user even after the termination of the contractual relationship (e.g. account suspension, exclusion). The data is stored only for the purpose and to the extent that it is possible to prevent the excluded user from opening a new account on Service Provider's website, for the benefit of other users of the platform, thus preserving and ensuring its secure operation.

01 · Identity

Name and contact of the data controller

Company name
E-GROUP ICT SOFTWARE Informatikai Zártkörűen Működő Részvénytársaság
Address
2 Alsó Törökvész út, Budapest 1022
EU VAT number
HU3665908
Website
www.egroup.hu
Policy available at
www.egroup.hu
E-mail
info@egroup.hu / egroup.hu/company/contact-us
Telephone
+36-1-371-2555
 

Definitions

GDPR (General Data Protection Regulation) is the Data Protection Regulation of the European Union.

Data processing

Any operation or set of operations on personal data or data files, whether automated or non-automated, in particular collecting, recording, registering, classifying, storing, modifying, using, querying, transferring or otherwise disclosing, harmonizing or interconnecting, blocking, deleting and destructing the data, as well as preventing their further use.

Data controller

Natural or legal person or organisation without legal personality, public authority, agency or any other body processing personal data on the grounds of a contract concluded with the Data controller.

Identifiable natural person

A natural person who is directly or indirectly identifiable, in particular by means of an identifier such as a name, identification number, location data, online identifier, or the physical, physiological, genetic, mental, economic, cultural or social identity of a natural person identifiable by one or more relevant factors.

Personal data

Any information relating to the identified or identifiable natural person (data subject); a natural person can be identified who is identifiable directly or indirectly, in particular on the basis of an identifier such as name, number, location, online identifier or one or more factors relating to the physical, physiological, genetic, mental, economic, cultural or social identity of the natural person.

Data subject

Any natural person identified or directly or indirectly identifiable on the basis of personal data.

Data subject's consent

A clear, voluntary and well-informed statement of the data subject's will, by means of a statement or other conduct that unequivocally expresses his or her will, that he or she consents to the processing of personal data concerning him or her.

Data breach

A security breach that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, personal data that is transmitted, stored, or otherwise managed.

Recipient

Any natural or legal person, public authority, agency or any other body to whom personal data are communicated, whether or not a third party. Public authorities that may have access to personal data in the context of an individual inquest in accordance with European Union or any Member State law shall not be considered as recipients; the processing of such data by these public authorities must comply with the applicable data protection rules in accordance with the purposes of data control.

Third party

A natural or legal person, public authority, agency or any other body other than the data subject, the controller, the processor or persons who have been authorized to process personal data under the direct processing of the data controller or data processor.

Privacy Policy

The data controller declares that personal data is managed in accordance with the provisions of this Privacy Policy and complies with the provisions of the relevant legislation, in particular with regard to the following.

01

The processing of personal data must be carried out lawfully and fairly and in a way that is transparent to the data subject.

02

Personal data may only be collected for specified, explicit and legitimate purposes.

03

The purpose of the processing of personal data must be appropriate and relevant, and only to the extent necessary.

04

Personal information must be accurate and up to date. Inaccurate personal data must be deleted immediately.

05

Personal data must be stored in such a way as to enable identification of data subjects only for as long as is necessary. A longer period is permitted only for archiving in the public interest, for scientific and historical research purposes or for statistical purposes.

06

Processing must ensure adequate security of the personal data, including protection against unauthorized or unlawful data control, accidental loss, destruction or damage, by means of appropriate technical or organizational measures.

The Service Provider must apply the principles of data protection to all information concerning all identified or identifiable natural persons.

 

Legal basis, purpose and scope of the processing

4.1 Criteria for processing

During Service Provider's data control, personal data may be processed if at least one of the following criteria is met:

Consent

The User concerned has given his or her voluntary informed consent to the processing of his or her personal data for one or more specific purposes — Article 6 (1) (a) GDPR — including e.g. receiving a newsletter or the use of cookies.

Contract

Processing is necessary for the performance of a contract in which the User is a concerned party, or prior to the conclusion of the contract for taking steps at the request of the data subject — Article 6 (1) (b) GDPR.

Legal obligation

Processing is necessary for the fulfillment of a legal obligation of the data controller, such as the fulfillment of an accounting obligation — Article 6 (1) (c) GDPR.

Legitimate interest

Processing is necessary to safeguard the legitimate interests of the data controller or of a third party, unless those interests take precedence over the interests or fundamental rights and freedoms of the data subject which require the protection of personal data, in particular if the data subject is a child — Article 6 (1) (f) GDPR.

The processing of all personal data relating to a data subject is based on voluntary consent, a legitimate interest substantiated by a balancing test, the performance of a contract or the fulfillment of a legal obligation.

If those who provide data to the Service Provider do not provide their own personal data, they are always obliged to obtain the consent of the data subjects. Service Provider excludes all liability for non-consent.

4.2 Registration

The purpose of data processing is providing service and contact. The legal basis for data processing for registration purposes is the consent of the data subject. Those involved in data processing are registered users of the website.

Duration of data control: the data processing is carried out until the consent is withdrawn. The data subject may withdraw his or her consent to the data processing at any time by sending a letter to the contact e-mail address. Service Provider stores personal data — in cases not otherwise indicated in this Privacy Policy — until the existence of the customer relationship and the enforcement of civil law claims.

The data will be deleted when the consent to the data processing is revoked. The data controller and its employees have the right to access the data. Data is stored electronically.

Modification or deletion of personal data can be initiated by e-mail, telephone or letter using the contact options provided above. The provision of personal data is absolutely necessary for identification in the databases and for maintaining communication.

4.3 Request for information

Service Provider provides you with the opportunity to send a request for information on the website. To do this, you must provide the following information: name, e-mail address, phone number, and additional information that may contain personal information.

Purpose
Making a personalized offer.
Legal basis
Your voluntary consent under Article 6 (1) (a) GDPR, based on adequate information.
Duration
Until the consent is withdrawn. Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.

4.4 Use of cookies

Technical cookies are essential for the operation of the website — the service provider is entitled to use them without your permission.

  • A cookie that stores the data you record: when you close your browser, these cookies are automatically deleted, they are only used to identify your computer, and your personal data is not stored.
  • User interface customization cookie: used to store user preferences related to the service that are not related to other persistent identifiers, such as cookies for the desired language or for the desired display format of results when querying.

The cookies listed below may only be used with your prior consent:

  • Cookies needed to increase performance: these cookies only identify your computer, they do not collect your personal data, only data related to the use of the Website, with Google Analytics cookies, e.g. to understand the behavior and characteristics of their users, which subpages did the user visit, how regularly and for how long did the visit last.
  • Functional cookies: allows you to restore your previous settings, thus providing a higher level of personalized service. It may also contain personal information you provide on the Website.
  • Targeted cookies: This allows us to deliver targeted, relevant advertisements to you, allow you to connect to social networking sites and they only identify your computer.

We use remarketing services to deliver our personalized ads to you:

Google Ads

Used to remember your recent searches, past interactions with individual advertisers' ads or search results, and visits to advertisers' websites. It uses cookies to track sales and other conversions that result from an ad and saves them to your computer when you click on an ad.

Google Analytics

Google's analytics tool that helps website and application owners get a more accurate picture of their visitors' activities. The Service may use cookies to collect information and report statistics about the use of the Website without personally identifying visitors for Google. In addition to site usage statistics, Google Analytics — along with some of the advertising cookies described above — can also be used to show more relevant ads on Google products and across the web: google.com/analytics

Facebook Pixel

A code embedded in the source code of the Website to serve personalized advertisements on Facebook to visitors of the Website: facebook.com/business/help

Legal basis for data processing: your voluntary consent under Article 6 (1) (a) of the GDPR, based on adequate information.

Duration of data processing: Until the consent is withdrawn.

Please note that the withdrawal of consent does not affect the lawfulness of the data processing carried out with your consent prior to the withdrawal.

4.5 Social media sites — extensions (facebook, instagram)

Extensions on the Website are disabled by default. Extensions will only be enabled if you click the button to enable them. By enabling the extension you are connecting to facebook.com or instagram.com and agree to the transfer of your data to the given service provider.

When you click the appropriate button, your browser transmits the relevant information directly to that social network and stores it there. More information about their data processing: facebook.com/about/privacy, help.instagram.com

4.6 Social media sites

In order to use the services, the system automatically logs the following data: the dynamic IP address of your computer; depending on your computer's settings, the type of browser and operating system you are using; activity related to the website; and the date of activity.

Legal basis: legitimate interest of the service provider under Article 6 (1) (f) GDPR. Duration of data processing: 90 days from creation.

4.7 Balance of interest test

Article 6 (1) (f) GDPR

Purpose of data processing: on the one hand technical use, such as analyzing the secure operation of servers, retrospective control and recording security deviations; on the other hand compiling site usage statistics and analyzing user needs for improving the quality of services.

Legitimate interest of the data controller: Service Provider has a legitimate interest in the availability and secure operation of the Website.

Rights and freedoms of the data subject: the data controller is not able to identify the data subject from the above data. The data stored in the log files is not linked to any other information that would allow the person behind the data to be identified. The processing does not affect the privacy of the data subject; his or her data protection rights and freedoms are not endangered.

As a result of the balancing test, it can be concluded that the interest of the data subject does not take absolute precedence over the legitimate interest of the service provider, and the data processing does not restrict the privacy of the data subject.

4.8 Data processing different from the above purposes

We may only process personal data relating to you for any purpose other than those set out above — in particular to increase the efficiency of the service or to conduct market research — with the prior determination of the processing of your data and with your consent.

This data may not be linked to your identifying data and may not be passed on to third parties without your consent. We are obliged to delete this data if the purpose of data processing has ceased or if you have so provided.

Only our own employees, agents and other contributors who are required to know the data processed in order to fulfill their duties have the right to access the personal data. We are obliged to ensure that those entitled to access the data we process comply with the provisions of this Privacy Policy and the applicable legislation at all times.

05 · Minors

Processing the personal data of minors

The processing of personal data relating to information society services offered directly to children is lawful if the child has reached the age of 16.

Pursuant to Articles 6 (1) (a) and 8 of the GDPR, the processing of personal data of a minor who has reached the age of 16 is lawful only if and to the extent that the data subject has given his or her consent to the processing of his or her personal data for one or more specific purposes.

In the case of a child under the age of 16, the processing of children's personal data is only lawful if and to the extent that the consent has been given or authorized by the person exercising parental control over the child. Service Provider hereby declares that it is not in a position to verify the consent described above.

 
06 · Key information

Important data processing information

The purpose of data processing is to enable Service Provider and Data Controller to provide appropriate additional services to the visitors of the Website and the persons registered on the website during the operation of the Website. The data subjects are the visitors and registered users of the Website.

Duration of data processing always depends on the specific user purpose, but the data must be deleted immediately if the original purpose has already been achieved. Personal data — in cases not otherwise indicated in this Privacy Policy — is stored until the existence of the customer relationship and the enforcement of civil law claims.

The data subject may request the data controller to access, rectify, delete or restrict the processing of personal data concerning him or her and to object to the processing of such personal data, as well as to ensure the exercise of the data subject's right to data portability.

Right to rectification and erasure of data. The data subject shall have the right, at the request of the data controller, to correct or supplement inaccurate personal data concerning him or her without undue delay, and shall have the right to delete personal data concerning him or her, whether accurate or inaccurate, without undue delay. The data controller is obliged to delete the personal data of the data subject without undue delay, unless there is another legal basis for the processing. If there is no legal impediment to the deletion, your data will be deleted.

Withdrawal of consent. The data subject may withdraw his or her consent at any time, but this shall not affect the lawfulness of the processing carried out prior to the withdrawal. Modification or deletion of personal data and withdrawal of consent can be initiated by e-mail, telephone or letter using the contact options provided above. The data controller and its employees have the right to access the data.

Filing a complaint. The person concerned may exercise the right to file a complaint with the supervisory authority at the contact details given in the Your Rights document.

If the person concerned wishes to have the benefits of registration, it is necessary to provide the requested personal data. The data subject is not obliged to provide personal data, and there are no adverse consequences for the non-provision of data. However, it is not possible to use certain functions of the Website without registration. You can give your consent to the data processing by intentionally and explicitly ticking the blank checkbox on the website dedicated to this purpose.

In order to get to know the users, make the service provider's activity easier and personalize the newsletter, other direct marketing inquiries and services, additional information can be provided based on the data subject's consent — for example where you first heard about the service provider's services, gender, date of birth, education, occupation, marital status, field of work, type of internet connection, operating system, type of browser, regularly visited pages and interests.

In addition to the above, the database contains whether the user requested an e-mail newsletter or not, and if so, what content was requested, and whether he or she consented to being served by the Service Provider for direct marketing purposes (e.g. by phone, SMS, e-mail or post).

You, as a data subject and user, may object to the processing of your personal data. In this regard you are entitled to proceed in accordance with the data processing information detailed above and this privacy notice, as well as the legislation described in it. Most of the information provided can be modified on the Website. You can initiate the deletion of the data from your own personal menu or user account.

 
07 · Visitors

Website visitor details

When visiting Service Provider's Website, Service Provider may record the users' IP address and the date of the visit for technical reasons and for the purpose of compiling statistics on user habits. The legal basis for the processing of data is the legitimate interest of the service provider.

IP addresses are recorded anonymously for statistical purposes; they do not contain the personal data of the visitors of the Website and cannot be linked to them. Duration of the storage of data: IP data is stored by the server for one month.

 

 
08 · Newsletter

Newsletter

As the operator of the Website, we declare that we fully comply with the relevant legal provisions regarding the information and descriptions published by us. We further declare that when subscribing to the newsletter we are not in a position to verify the authenticity of the contact information or to establish that the information provided relates to an individual or a business. We treat companies that contact us as customer partners.

The purpose of data processing is to send professional brochures and electronic messages containing advertisements, information and newsletters, from which the recipient can unsubscribe at any time without consequences — even if their business has been terminated, they left the business, or someone has provided us with the recipient's contact information.

The legal basis for data processing is the consent of the user. The user may in advance and expressly consent to being contacted by Service Provider with advertising offers, information and other items at the e-mail address provided during registration. If you want to receive a newsletter from us, you must provide the necessary information; if you do not provide data, we will not be able to send you a newsletter.

Duration of data processing: the data will be processed until the consent is revoked. The user may revoke consent at any time by sending a letter or e-mail to the contact address, or based on the link in the newsletters sent out. Personal data — in cases not otherwise indicated in this Privacy Policy — is stored until the existence of the customer relationship and the enforcement of civil law claims. The data controller and its employees have the right to access the data. Data is stored electronically.

Scope of data processed
Specific purpose
Name
Identification, contact.
E-mail
Identification, contact.
Date of subscription
Technical information operation.
IP address
Technical information operation.

Please note that neither your username nor your e-mail address is required to include personally identifiable information. It is not necessary for the user name or e-mail address to contain the user's real name — the user is completely free to decide what username or e-mail address to enter. An e-mail address used for contact is absolutely necessary for the newsletter or professional information to reach its destination.

 
09 · Processors

Data processors

 
01 · Hosting provider

Service Provider also acts as a hosting provider.

Company
E-Group ICT SOFTWARE Zrt.
Headquarters
2 Alsó Törökvész út, Budapest 1022
Telephone
+36-1-371-2555
E-mail
info@egroup.hu

The data provided by the user is stored on a server operated by the hosting provider. The data can only be accessed by Service Provider's employees and the employees operating the server, and all of them are responsible for the secure handling of the data.

Activity: hosting service, server service. Purpose: to make the website available and to ensure its operation. Scope of data processed: all personal data provided by the data subject.

Duration and deadline for deletion: data processing runs until the end of the operation of the website or a contractual agreement between the operator of the website and the hosting provider. If necessary, the user concerned can also request the deletion of his or her data by contacting the hosting provider.

Legal basis: the consent of the user concerned and statutory data processing — Section 5 (1) and Article 6 (1) (a) of the Information Act, and Section 13/A (3) of Act CVIII of 2001 on certain issues of electronic commerce services and information society services.

Our servers, on which our egroup.hu system runs, are protected by a firewall and located in a secure physical environment at a hosting provider or properly locked. In the event of a physical or technical incident, the server service provider ensures the availability and restoration of the website data by means of a regular backup. Our server operator does not have access to personal data.

 
02 · Analytics
Company
Google Inc.
Headquarters
1600 Amphitheatre Parkway, Mountain View, US, CA 94043
Privacy policy
google.com/policies/privacy
Contact
Google Számítástechnikai Szolgáltató Kft., 26-28 Árpád fejedelem útja, Budapest 1023
E-mail
googlekft@google.com

We use Google Analytics software to obtain independent traffic and other web analytics data from the Website. By using the Website you consent to the processing of your data by Google.

We reserve the right to use additional data processors in addition to those listed above by publishing the names and addresses of the additional data processors in a way that is accessible to users at the beginning of data processing at the latest.

10.1 · Information and access

Right to request information and access

As a user, you can request information from us about the following via the contact details provided:

01

The categories of personal data concerned.

02

The recipients with whom we have communicated or will communicate your personal data, in particular third country recipients or international organizations.

03

The duration of the storage of personal data or, if this is not possible, the criteria for determining this period.

04

Your right to request us to rectify, delete or restrict the processing of your personal data and to object to the processing of such personal data.

05

The right to lodge a complaint with a supervisory authority.

06

If the data was not collected from you, all available information about their source.

Upon your request we will send you information immediately, but within 30 days, to the e-mail contact you provided. The information is free of charge. We will provide you with a copy of the personal data that is the subject of data processing. For any additional copies you request, the data controller will charge a reasonable fee based on administrative costs. If you have submitted your application electronically, we will provide the information in a widely used electronic format, unless you request otherwise.

If the request is manifestly unfounded or particularly repetitive due to its excessive nature, we may charge a reasonable fee taking into account the administrative costs involved, or refuse to act on the request. It is in all cases up to us to prove that the request is manifestly unfounded or excessive.

 
10.2 · Rectification

Right of rectification

You, as an affected user, may request us to change any of your details through the contact details provided. We will take action on your request immediately, but within a maximum of 30 days, and we will send you information by e-mail. If true or additional information is not available, the rectifications and additions will be made through a supplementary declaration.

 
10.3 · Cancellation

Right to cancellation

We are required to delete your personal data if:

its processing is illegal;
you withdraw your consent on which the data processing is based, or request the deletion of your data and there is no other legal basis for the data processing;
it is incomplete or incorrect — and this condition cannot be legally remedied — provided that cancellation is not precluded by law;
the purpose of data processing has ceased, or the term for the storage of data specified by law has expired;
the deletion of the data has been ordered by a court or the Authority.
 
10.4 · Blocking

Right to blocking

You, as the user concerned, may request that your data be blocked from us via the contact details provided, or on the basis of the information available to you it is presumed that the deletion would harm your legitimate interests. Personal data blocked in this way may only be processed for as long as the purpose of the data processing which precluded the deletion of personal data exists. At your request we will do this immediately, but within a maximum of 30 days, and we will send information to the e-mail contact you provided.

 
10.5 · Objection

Right to object

You may object to the data processing via the contact details provided. We will investigate the objection as soon as possible after the submission of the application, but not later than within 15 days, make a decision on its merits, and inform you about the decision by e-mail.

You may object to the processing of your personal data:

if the processing or transfer of personal data is necessary only for the fulfillment of our legal obligation or for the enforcement of a legitimate interest of us or a third party, except in the case of mandatory data processing;
if the use or transfer of personal data is for the purpose of direct business acquisition, public opinion polling or scientific research;
in other cases specified by law.

If the objection is justified, we are obliged to terminate the processing of data — including further data collection and transfer — and to block the data, as well as to notify all persons to whom we have previously transferred the personal data concerned by the objection and who are obliged to take action to enforce the right to objection. If you do not agree with our decision, or if we miss the 15-day deadline, you can appeal against the decision to the court upon receipt of the notification of the decision or within 30 days from the last day of the deadline.

 
10.6 · Restriction

Right to restrict data processing

We restrict data processing if any of the following is true:

you dispute the accuracy of personal information;
the data processing is illegal and you oppose the deletion of the data and instead ask for a restriction on its use;
we no longer need personal data for data processing purposes, but you require it to make, enforce or protect legal claims;
you have objected to the data processing.

If the processing is subject to restrictions, such personal data may be processed — with the exception of storage — only with your consent, or for the purpose of making, enforcing or protecting legal claims, or protecting the rights of another natural or legal person, or in the important public interest of the European Union or a Member State.

 
10.7 · Portability

Right to data portability

You have the right to receive personal data about you provided to us in a structured, widely used, machine-readable format, if technically feasible, if the data processing is based on your consent or contract and the data processing is automated.

If we cannot comply

If your request for rectification, restriction or deletion cannot be complied with, we will inform you in writing within 25 days of receipt of the request of the rejection of the request and the reasons for the rejection.

Your rights under section 10 may be restricted by law for the external and internal security of the state — such as national defense, national security, the prevention or prosecution of criminal offenses, the security of law enforcement, and the economic or financial interests of the state or local government, or the significant economic or financial interests of the European Union — and to prevent and detect disciplinary and ethical violations related to the pursuit of occupations, breaches of employment law and health and safety obligations, including inspection and supervision, and to protect the rights of the data subject or others.

 
10.8 · Enforcement

Possibility of enforcement

In case of illegal data processing experienced by you as the user concerned, notify Service Provider so that the legal status can be restored within a short time. We will do our best to solve the problem outlined.

 
10.8.1 · Complaints management

How we handle a complaint

Personal data
Purpose of data processing
Surname and family name
Identification, contact.
Telephone number
Contact.
E-mail
Contact.
Other
Handling issues arising regarding the Services.

Data subjects: all data subjects who make a complaint using the service. Duration: data are stored until the enforcement of civil law claims. Personal data may be processed by the data controller's employees, respecting the above principles.

The data subject may request the data controller to access, rectify, delete or restrict the processing of personal data concerning him or her, may object to the processing, and has the right to data portability and withdrawal of consent at any time.

Access to, deletion, modification or restriction of the processing of personal data, portability of data and objection to data processing can be initiated in the following ways:

By post
2 Alsó Törökvész út, Budapest 1022
By e-mail
info@egroup.hu
contact form
By phone
+36-1-371-2555

Legal basis: data subject's consent, Article 6 (1) (c) GDPR, Privacy Act Section 5 (1) and Article 17/A § (7) of Act CLV of 1997 on consumer protection.

We inform you that the provision of personal data is based on a contractual obligation: (a) the processing of personal data is a precondition for concluding the contract; (b) it is required to provide personal information so that we can handle your complaint; (c) failure to provide information has the consequence that we are unable to handle your complaint.

 
10.8.2 · Data breach

Data breach notice

If the data breach is likely to pose a high risk to the rights and freedoms of natural persons, we will inform you regarding the data breach without undue delay.

The information provided to the data subject shall clearly and intelligibly describe the nature of the data breach and the name and contact details of the data protection officer or other contact person who provides further information; the likely consequences of the data breach must be disclosed; and the measures taken or planned by the data controller to remedy the data breach must be disclosed, including, where appropriate, measures taken to mitigate any adverse consequences arising from the data breach.

The data subject need not be informed if any of the following conditions are met:

the data controller has implemented appropriate technical and organizational protection measures and these have been applied to the data affected by the data breach — in particular measures such as encryption which make the data incomprehensible to persons not authorized to access personal data;
the data controller has taken further measures following the data breach to ensure that the high risk to the data subject's rights and freedoms is no longer likely to materialize;
providing information to the data subject would require a disproportionate effort. In such cases, data subjects shall be informed through publicly available information or a similar measure ensuring an equally effective manner.

If the data controller has not yet notified the data subject of the data breach, the supervisory authority may, after considering whether the data breach is likely to involve a high risk, order that the data subject be informed.

72h

Report a data breach to the authority. The data breach shall be reported by the data controller without undue delay and, if possible, no later than 72 hours after becoming aware of it to the competent supervisory authority under Article 55 GDPR (e.g. NAIH — Hungarian National Authority for Data Protection and Freedom of Information), unless the data breach is unlikely to incur risks to the rights and freedoms of natural persons. If the notification is not made within 72 hours, the reasons for the delay must be provided.

 
Escalation

Authority and court

If you consider that the legal situation cannot be restored, notify the authority or the court. Complaints against possible violations of the data controller can be made to the Hungarian National Authority for Data Protection and Freedom of Information.

 
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Postal address
1363 Budapest, Pf.: 9.
Address
9-11 Falk Miksa, Budapest 1055
Telephone
+36 (1) 391-1400
Fax
+36 (1) 391-1410
E-mail
ugyfelszolgalat (at) naih.hu
Website
naih.hu

Competent court: your place of residence, or the General Court with jurisdiction over the place of residence.

 
11 · Legislation

Legislation underlying data processing

In preparing this Privacy Policy, we have complied with the following legislation.

GDPR

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC.

CXII / 2011

Act on the Right to Information Self-Determination and Freedom of Information (Privacy Act).

LXVI / 1995

Act on Public Documents, Archives and the Protection of Private Archival Material.

XLVII / 2008

Act on the Prohibition of Unfair Commercial Practices against Consumers.

CVIII / 2001

Act on Certain Issues of Electronic Commerce Services and Information Society Services, mainly Section 13/A ("Eker tv").

XLVIII / 2008

Act on the basic conditions and certain restrictions of commercial advertising, especially § 6.

XC / 2005

Act on Electronic Freedom of Information.

C / 2003

Act on electronic communications, specifically § 155.

Opinion 16/2011

On the EASA / IAB Recommendation on Best Practices for Behavioral Online Advertising.

V / 2013

Section 2:43 e) of the Act on the Civil Code ("Civil Code").

VI / 1998

Act promulgating the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, done at Strasbourg on 28 January 1981.

CXIX / 1995

Act on the management of name and address data for the purpose of research and direct business acquisition ("Katv.").

NAIH

Recommendation of the Hungarian National Authority for Data Protection and Freedom of Information on data protection requirements for prior information.

Exercise a right

Write to us and we answer within 30 days.

Read: Your rights

From the Work

News from the work. Opinions on what it means. A few times a year.


E-Group

A sovereign infrastructure company.

Built in Budapest.

Running in production since 1993.

Technology should answer to people, not the other way around.

E-Group ICT Software Zrt.

Alsó Törökvész út 2.

H-1022 Budapest,

HUNGARY

Company registration number: 01 10 045390

HUN Tax number: 13665908-2-41

EU Tax number: HU13665908

Follow the Work

The Company

  • Home
  • Platform
  • Solutions
  • Engage
  • Industries
  • Principles
  • The Work
  • Thinking
  • About
  • Take a Position

Contact

  • info@egroup.hu
  • Budapest, Hungary
  • +36 1 371 2555

Copyright 2026 E-Group

Privacy Policy IT SECURITY POLICY

We use cookies on our site to enhance your user experience, provide personalized content, and analyze our traffic.